DMS100: HIPAA Exam with Complete
Solutions
what is the purpose of the HIPAA Security Rule?
- to protect the privacy and security of patient's health information
- to establish standards for electronic health transactions
- to ensure portability of health insurance coverage
- to provide guidelines for the secure handling of electronic PHI - ANSWER-to provide
guidelines for the secure handling of electronic PHI
true or false: HIPAA allows patients to request a copy of their medical records and
receive them within 30 days - ANSWER-true
which of the following is an example of a technical safeguard under HIPAA?
- conducting regular risk assessments
- implementing access controls and user authentication measures
- developing a privacy policy
- training employees on HIPAA regulations - ANSWER-implementing access controls
and user authentication measures
true or false: HIPAA allows healthcare providers to share patient information for
research purposes without obtaining the patient's consent - ANSWER-true
which of the following is not a required component of a HIPAA-complaint authorization
form?
- purpose of the disclosure
- patient's date of birth
- types of information to be disclosed
- expiration date of the authorization - ANSWER-patient's date of birth
true or false: HIPAA violations can result in both civil and criminal penalties - ANSWER-
true
true or false: HIPAA requires covered entities to provide training on HIPAA policies and
procedures to their employees - ANSWER-true
true or false: HIPPA allows patients to access and request corrections to their medical
records - ANSWER-true
true or false: HIPAA applies only to healthcare providers and not to business associates
or subcontractors - ANSWER-false
, true or false: HIPAA requires patients to sign consent forms before their health
information can be shared - ANSWER-true
which of the following is an example of physical safeguards under HIPAA?
- encrypting electronic PHI
- restricting access to PHI to authorized personnel
- using secure locks and passwords
- all of the above - ANSWER-all of the above
what is the penalty for a HIPAA violation?
- written warning
- monetary fine
- license revocation
- community service - ANSWER-monetary fine
true or false: HIPPA applies only to healthcare providers and not to healthcare payers -
ANSWER-false
what is the minimum necessary standard under HIPAA?
- healthcare providers should use the minimum amount of PHI necessary to accomplish
the intended purpose
- healthcare providers should store the minimum amount of PHI necessary for billing
purposes
- healthcare providers should disclose the minimum amount of PHI necessary for
research purposes
- healthcare providers should delete all unnecessary PHI from their systems -
ANSWER-healthcare providers should use the minimum amount of PHI necessary to
accomplish the intended purpose
true or false: HIPAA applies only to electronic health records and not to paper records -
ANSWER-false
which of the following is an example of administrative safeguards under HIPAA?
- implementing security measures to protect electronic PHI
- conducting regular risk assessments and audits
- training employees on HIPAA policies and procedures
- all of the above - ANSWER-all of the above
what should a sonographer do if they suspect a breach of patient privacy or security?
- report it to their supervisor or privacy officer
- ignore it unless directly involved
- notify the patient's family members
- share the information with colleagues for discussion - ANSWER-report it to their
supervisor or privacy officer
Solutions
what is the purpose of the HIPAA Security Rule?
- to protect the privacy and security of patient's health information
- to establish standards for electronic health transactions
- to ensure portability of health insurance coverage
- to provide guidelines for the secure handling of electronic PHI - ANSWER-to provide
guidelines for the secure handling of electronic PHI
true or false: HIPAA allows patients to request a copy of their medical records and
receive them within 30 days - ANSWER-true
which of the following is an example of a technical safeguard under HIPAA?
- conducting regular risk assessments
- implementing access controls and user authentication measures
- developing a privacy policy
- training employees on HIPAA regulations - ANSWER-implementing access controls
and user authentication measures
true or false: HIPAA allows healthcare providers to share patient information for
research purposes without obtaining the patient's consent - ANSWER-true
which of the following is not a required component of a HIPAA-complaint authorization
form?
- purpose of the disclosure
- patient's date of birth
- types of information to be disclosed
- expiration date of the authorization - ANSWER-patient's date of birth
true or false: HIPAA violations can result in both civil and criminal penalties - ANSWER-
true
true or false: HIPAA requires covered entities to provide training on HIPAA policies and
procedures to their employees - ANSWER-true
true or false: HIPPA allows patients to access and request corrections to their medical
records - ANSWER-true
true or false: HIPAA applies only to healthcare providers and not to business associates
or subcontractors - ANSWER-false
, true or false: HIPAA requires patients to sign consent forms before their health
information can be shared - ANSWER-true
which of the following is an example of physical safeguards under HIPAA?
- encrypting electronic PHI
- restricting access to PHI to authorized personnel
- using secure locks and passwords
- all of the above - ANSWER-all of the above
what is the penalty for a HIPAA violation?
- written warning
- monetary fine
- license revocation
- community service - ANSWER-monetary fine
true or false: HIPPA applies only to healthcare providers and not to healthcare payers -
ANSWER-false
what is the minimum necessary standard under HIPAA?
- healthcare providers should use the minimum amount of PHI necessary to accomplish
the intended purpose
- healthcare providers should store the minimum amount of PHI necessary for billing
purposes
- healthcare providers should disclose the minimum amount of PHI necessary for
research purposes
- healthcare providers should delete all unnecessary PHI from their systems -
ANSWER-healthcare providers should use the minimum amount of PHI necessary to
accomplish the intended purpose
true or false: HIPAA applies only to electronic health records and not to paper records -
ANSWER-false
which of the following is an example of administrative safeguards under HIPAA?
- implementing security measures to protect electronic PHI
- conducting regular risk assessments and audits
- training employees on HIPAA policies and procedures
- all of the above - ANSWER-all of the above
what should a sonographer do if they suspect a breach of patient privacy or security?
- report it to their supervisor or privacy officer
- ignore it unless directly involved
- notify the patient's family members
- share the information with colleagues for discussion - ANSWER-report it to their
supervisor or privacy officer